Checkmarx supply chain attack impacts Bitwarden npm distribution path
ID: 51979f70-20c9-561b-befa-7f8b2fc04b5a
STIX ID: report--51979f70-20c9-561b-befa-7f8b2fc04b5a
Feed Name: Security Affairs
Threat Score
Researchers report that the Checkmarx supply-chain campaign briefly compromised the Bitwarden CLI npm distribution (version 2026.4.0) via a malicious preinstall hook introduced by a compromised GitHub Action; the multi-stage payload harvests SSH keys, cloud credentials, tokens, and other secrets, exfiltrates them to attacker-controlled repositories, and can propagate using stolen credentials, with IOCs published and the malicious package revoked by Bitwarden.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
